CN107135195B - The detection method and device of abnormal user account - Google Patents

The detection method and device of abnormal user account Download PDF

Info

Publication number
CN107135195B
CN107135195B CN201710090744.0A CN201710090744A CN107135195B CN 107135195 B CN107135195 B CN 107135195B CN 201710090744 A CN201710090744 A CN 201710090744A CN 107135195 B CN107135195 B CN 107135195B
Authority
CN
China
Prior art keywords
user account
invited user
account
network address
duration
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201710090744.0A
Other languages
Chinese (zh)
Other versions
CN107135195A (en
Inventor
杜玉丹
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ping An Technology Shenzhen Co Ltd
Original Assignee
Ping An Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ping An Technology Shenzhen Co Ltd filed Critical Ping An Technology Shenzhen Co Ltd
Priority to CN201710090744.0A priority Critical patent/CN107135195B/en
Publication of CN107135195A publication Critical patent/CN107135195A/en
Application granted granted Critical
Publication of CN107135195B publication Critical patent/CN107135195B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Abstract

The present invention relates to a kind of detection method and device of abnormal user account, the method includes:Obtain user account;Inquiry multiple invited user accounts corresponding with the user account;Obtain the network address of each invited user account institute registration terminal;Judge whether the Subnet Identification in the network address got is identical;If the Subnet Identification in the network address got is identical, the multiple invited user account is labeled as abnormality.The detection method and device of abnormal user account provided by the invention, directly acquire the network address of each invited user account institute registration terminal, Subnet Identification in the network address got judges whether multiple invited user accounts are abnormal user account, improves the detection efficiency of abnormal user.

Description

The detection method and device of abnormal user account
Technical field
The present invention relates to technical field of data processing, more particularly to a kind of detection method and dress of abnormal user account It puts.
Background technology
With the development of Internet technology, there are many internet products.User when using these internet products, Generally require registration user account corresponding with internet product.Due to a large amount of appearance of internet product, certainly exist Similar internet product inevitably will appear competition between similar internet product.In competition process, pass through various battalion Pin means invite multiple user's registration accounts to increase user be relatively common especially by the user for rewarding registered account Number mode increase number of users.Some users can then be used to obtain more reward by inviting come malice batch registration Family account, however the user account of these batch registrations can't be used really, it is only simple to log in.
In traditional abnormal user detection technique, detect whether user account is different by the use data of user account Normal user account,, can not be according to using data to note batch there is no using data for the user account not used really The user account of volume is detected.Moreover according to using data that can only be detected to single user's account, if to batch registration User account be detected, then detection efficiency is low.
Invention content
Based on this, it is necessary to for abnormal user detection efficiency it is low the problem of, a kind of inspection of abnormal user account is provided Survey method and apparatus.
A kind of detection method of abnormal user account, the method includes:
Obtain user account;
Inquiry multiple invited user accounts corresponding with the user account;
Obtain the network address of each invited user account institute registration terminal;
Judge whether the Subnet Identification in the network address got is identical;
If the Subnet Identification in the network address got is identical, by the multiple invited user account Labeled as abnormality.
In one of the embodiments, corresponding with the user account multiple invited user accounts of the inquiry it Afterwards, it further includes:
Obtain the corresponding account registion time of each invited user account;
Account registion time according to getting is ranked up invited user account;
Account registion time according to corresponding to the invited user account after sequence, obtains two neighboring invited user The registration interval duration of account;
By the registration interval duration compared with predetermined interval duration;
If the registration interval duration is less than the predetermined interval duration, each invited user of acquisition is performed The step of network address of account institute registration terminal.
In one of the embodiments, corresponding with the user account multiple invited user accounts of the inquiry it Afterwards, it further includes:
Obtain the corresponding log duration of each invited user account;
Judge whether the log duration extracted is less than default log duration;
If the log duration extracted is less than the default log duration, performs and described obtain each described be invited to The step of network address of user account institute registration terminal.
In one of the embodiments, it is described by the multiple invited user account labeled as after abnormality, also Including:
Checking request is sent to the invited user account institute registration terminal of label;
Obtain the verification information that the terminal is returned according to the checking request;
The invited user account of the label is verified according to the verification information;
If being verified, label is cancelled to the invited user account of the label.
In one of the embodiments, it is described by the multiple invited user account labeled as after abnormality, also Including:
The Subnet Identification is added to abnormal Subnet List;
Receive account registration request;
Extract the network address in account registration request;
Inquiry is with the presence or absence of Subnet Identification corresponding with the network address of extraction in the abnormal Subnet List;
If inquiring, refuse the account registration request.
The detection method of above-mentioned abnormal user account inquires multiple invited users corresponding with the user account got Account obtains the network address of each invited user account institute registration terminal, and the subnet in network address is got by judging Identify whether it is identical, if the Subnet Identification in the network address got is identical, then it represents that multiple invited user accounts be Terminal under same subnet is logged in, and multiple invited user accounts are labeled as abnormality.It is each invited without basis Please the use data of user account individually each invited user account is detected, directly acquire each invited user account The network address of institute's registration terminal, the Subnet Identification in the network address got judge that multiple invited user accounts are No is abnormal user account, improves the detection efficiency of abnormal user.
A kind of detection device of abnormal user account, described device include:
User account acquisition module, for obtaining user account;
User account enquiry module, for inquiring multiple invited user accounts corresponding with the user account;
Network address acquisition module, for obtaining the network address of each invited user account institute registration terminal;
Subnet Identification judgment module, for judging whether the Subnet Identification in the network address got is identical;
User account mark module, if the Subnet Identification in the network address got is identical, by institute Multiple invited user accounts are stated labeled as abnormality.
Described device further includes in one of the embodiments,:
Registion time acquisition module, for obtaining the corresponding account registion time of each invited user account;
User account sorting module, for being arranged according to the account registion time got invited user account Sequence;
It is spaced duration and obtains module, for the account registion time according to corresponding to the invited user account after sequence, Obtain the registration interval duration of two neighboring invited user account;
Be spaced duration comparison module, for by the registration interval duration compared with predetermined interval duration;
If the network address acquisition module is additionally operable to the registration interval duration less than the predetermined interval duration, obtain The network address of each invited user account institute registration terminal.
Described device further includes in one of the embodiments,:
Log duration acquisition module, for obtaining the corresponding log duration of each invited user account;
Log duration judgment module, for judging whether the log duration extracted is less than default log duration;
If the network address acquisition module, which is additionally operable to the log duration extracted, is less than the default log duration, Obtain the network address of each invited user account institute registration terminal.
Described device further includes in one of the embodiments,:
Checking request sending module, for sending checking request to the invited user account institute registration terminal of label;
Verification information returns to module, for obtaining the verification information that the terminal is returned according to the checking request;
User account authentication module, for being tested according to the verification information the invited user account of the label Card;
Label cancels module, for being verified according to the verification information to the invited user account of the label When, label is cancelled to the invited user account of the label.
Described device further includes in one of the embodiments,:
Subnet Identification add module, for the Subnet Identification to be added to abnormal Subnet List;
Registration request receiving module, for receiving account registration request;
Network address extraction module, for extracting the network address in the account registration request;
Subnet Identification enquiry module, for being inquired in the abnormal Subnet List with the presence or absence of the network address with extraction Corresponding Subnet Identification;
Registration request refuses module, if for inquiring the network address with extraction in the abnormal Subnet List During corresponding Subnet Identification, refuse the account registration request.
The detection device of above-mentioned abnormal user account inquires multiple invited users corresponding with the user account got Account obtains the network address of each invited user account institute registration terminal, and the subnet in network address is got by judging Identify whether it is identical, if the Subnet Identification in the network address got is identical, then it represents that multiple invited user accounts be Terminal under same subnet is logged in, and multiple invited user accounts are labeled as abnormality.It is each invited without basis Please the use data of user account individually each invited user account is detected, directly acquire each invited user account The network address of institute's registration terminal, the Subnet Identification in the network address got judge that multiple invited user accounts are No is abnormal user account, improves the detection efficiency of abnormal user.
Description of the drawings
Fig. 1 is the applied environment figure of the detection method of abnormal user account in one embodiment;
Fig. 2 is the structure diagram of the server in the detecting system of abnormal user account in one embodiment;
Fig. 3 is the flow diagram of the detection method of abnormal user account in one embodiment;
Fig. 4 is the flow diagram of the detection method of abnormal user account in another embodiment;
Fig. 5 is flow diagram the step of invited user account is verified in one embodiment;
Fig. 6 is flow diagram the step of account registration request is handled in one embodiment;
Fig. 7 is the structure diagram of the detection device of abnormal user account in one embodiment;
Fig. 8 is the structure diagram of the detection device of abnormal user account in another embodiment;
Fig. 9 is the structure diagram of the detection device of abnormal user account in further embodiment;
Figure 10 is the structure diagram of the detection device of abnormal user account in another embodiment.
Specific embodiment
In order to make the purpose , technical scheme and advantage of the present invention be clearer, with reference to the accompanying drawings and embodiments, it is right The present invention is further elaborated.It should be appreciated that the specific embodiments described herein are merely illustrative of the present invention, and It is not used in the restriction present invention.
Fig. 1 is the applied environment figure of the detection method of abnormal user account in one embodiment.With reference to Fig. 1, this is used extremely The detection method of family account is applied to the detecting system of abnormal user account.The detecting system of abnormal user account includes terminal 110 and server 120, wherein terminal 110 connect by network with server 120.Terminal 110 can be specifically desktop computer, At least one of laptop, tablet computer, smart mobile phone and personal digital assistant.Terminal 110 can be one or more It is a.
Fig. 2 is the internal structure signal of server 120 in the detecting system of Fig. 1 abnormal user accounts in one embodiment Figure.As shown in Fig. 2, the server 120 includes the processor, non-volatile memory medium, memory storage connected by system bus Device and network interface.Wherein, the non-volatile memory medium of server 120 is stored with operating system, database, further includes one kind The detection device of abnormal user account, the detection device of the abnormal user account are used to implement a kind of detection of abnormal user account Method.Processor calculates and control ability for providing, and supports the operation of entire server 120, the memory storage in server 120 Device provides environment for the operation of the detection device of the abnormal user account in non-volatile memory medium, can be deposited in the built-in storage Computer-readable instruction is contained, when which is executed by processor, may be such that processor performs a kind of abnormal use The detection method of family account.Network interface is used to carry out network communication with terminal.
As shown in figure 3, in one embodiment, a kind of detection method of abnormal user account is provided, the present embodiment is with this Server 120 that method is particularly applicable in the detecting system of Fig. 1 abnormal user accounts illustrates.This method specifically includes Following steps:
S302 obtains user account.
Specifically, server 120 obtains the account detection instruction that terminal 110 is sent, and detects instruction extraction according to account and uses Family account list is successively read user account according to putting in order in user account list.Account detection instruction is for controlling The instruction that control server 120 is detected user account.User account list includes having registered the user account of completion.
S304 inquires multiple invited user accounts corresponding with user account.
Specifically, store user account pass corresponding with invited user account in server 120 or user account list System.Invited user account is the user account of user account invitation registration.Server 120 is after user account is got, root According to correspondence from storage or inquiry and the corresponding invited user account of user account of acquisition in user account list, look into The invited user account ask is at least two.
In one embodiment, it is further included after S304:Obtain the corresponding log duration of each invited user account;Judge Whether the log duration extracted is less than default log duration;If the log duration extracted is less than default log duration, hold Row S306.
Specifically, server 120 obtains the corresponding login time of each invitation user account and post-set time, uses post-set time It subtracts login time and obtains the corresponding log duration of each invited user account.Server 120 logs in log duration with default Duration is compared, if log duration is less than default log duration, shows that multiple invited user accounts for suspicious account, need Further multiple invited user accounts are detected according to the network address of each invited user account institute registration terminal.
In one embodiment, after obtaining the corresponding log duration of each invited user account, server 120 can be with The corresponding log duration of each invited user account is compared, if the corresponding log duration phase of each invited user account Deng then judging whether the log duration extracted is less than default log duration again.
S306 obtains the network address of each invited user account institute registration terminal.
Specifically, for terminal 110 when logging in invited user account, network address can be uploaded to server by terminal 110 120.Server 120 by the network address that terminal 110 uploads it is corresponding with the invited user account logged in terminal 110 storage. Server 120 is inquired after multiple invited user accounts corresponding with user account are inquired in the network address of storage The network address of the corresponding registration terminal of each invited user account.
S308 judges whether the Subnet Identification in the network address got is identical.
Specifically, server 120 is with getting the network of each corresponding registration terminal of invited user account Behind location, extract the Subnet Identification in each network address, the Subnet Identification in more each network address whether all same.Network Location includes the device identification in Subnet Identification and subnet, and network address can be IP (Internet Protocol, internet Agreement) address.
For example, the IP address of terminal then identifies the subnet of terminal place subnet for 192.168.3.4 with 192.168.3.0 Mark, 0.0.0.4 represent the device identification of terminal in the subnet for being 192.168.3.0 in Subnet Identification, Subnet Identification and equipment Mark forms the IP address of terminal.
If the Subnet Identification in the network address got is identical, multiple invited user accounts are labeled as by S310 Abnormality.
Specifically, if by the Subnet Identification all same in the network address that relatively determines to get, represent that these are invited Please user account be batch registration abnormal user account, server 120 will inquire multiple quilts corresponding with user account User account is invited to be labeled as abnormality.Can be specifically that server 120 is marked for multiple invited user accounts addition exception Note.Server 120 can also be defined the access right of invited user account.
In one embodiment, server 120 is getting each corresponding registration terminal of invited user account Network address after, the network address got is compared.If the network address got is identical, server 120 will be more A invited user account is labeled as abnormality.If the network address got differs, server 120 judges what is got Whether the Subnet Identification in network address is identical.
In the present embodiment, multiple invited user accounts corresponding with the user account got are inquired, obtain each invited Please user account institute registration terminal network address, it is whether identical by judging to get Subnet Identification in network address, if Subnet Identification in the network address got is identical, then it represents that multiple invited user accounts are the terminals under same subnet It is logged in, multiple invited user accounts is labeled as abnormality.Without the use according to each invited user account Data are individually detected each invited user account, directly acquire the network of each invited user account institute registration terminal Address, the Subnet Identification in the network address got judge whether multiple invited user accounts are abnormal user account Number, improve the detection efficiency of abnormal user.
As shown in figure 4, in one embodiment, providing a kind of detection method of abnormal user account, this method is specifically wrapped Include following steps:
S402 obtains user account.
S404 inquires multiple invited user accounts corresponding with user account.
S406 obtains the corresponding account registion time of each invited user account.
Specifically, when invited user account is registered, server 120 is recorded when registering each invited user account Account registion time, the account registion time storage corresponding with each invited user account that server 120 records.Server 120 After multiple invited user accounts corresponding with the user account of acquisition are inquired, it is corresponding to inquire each invited user account Account registion time.
In one embodiment, can also include after S404:Obtain the corresponding log duration of each invited user account; Judge whether the log duration extracted is less than default log duration;If the log duration extracted is less than default log duration, Then perform S406.
S408 is ranked up invited user account according to the account registion time got.
Specifically, it after server 120 gets the corresponding account registion time of each invited user account, is noted according to account The time sequencing of volume time is ranked up invited user account.It specifically can be according to account registion time by early to evening Sequentially, it can also be according to account registion time by evening to early sequence.
S410, the account registion time according to corresponding to the invited user account after sequence obtain two neighboring invited Please user account registration interval duration.
Specifically, server 120 extracts two neighboring invited user account after to user account is invited to be ranked up Corresponding account registion time carries out additive operation according to the account registion time extracted and obtains two neighboring invited user The registration interval duration of account.Server 120 obtains multiple registration interval durations.
S412, by registration interval duration compared with predetermined interval duration.
Specifically, server 120 obtains predetermined interval duration, and server 120 is pre- by the registration interval duration being calculated If interval duration is compared, determine whether the multiple registration interval durations being calculated are both less than predetermined interval duration.
S414 if registration interval duration is less than predetermined interval duration, obtains each invited user account institute registration terminal Network address.
Specifically, server 120 is respectively less than predetermined interval duration by comparing determining registration interval duration, represents multiple quilts Invitation user account is suspicious account, needs further to detect multiple invited user accounts, server 120 obtains respectively The network address of invited user account institute registration terminal, according to the network address got to multiple invited user accounts into Row detection.Wherein, predetermined interval duration is set as any time between 5 seconds to 30 seconds, 5 seconds, 10 seconds, 15 seconds, 20 seconds and 30 Any one of second.
In one embodiment, server 120 according to obtained multiple registration interval duration calculations be averaged registration interval when It is long, average registration interval duration is compared with predetermined interval duration, if average registration interval duration is less than predetermined interval Long, then server 120 obtains the network address of each invited user account institute registration terminal, according to the network address pair got Multiple invited user accounts are judged.
S416 judges whether the Subnet Identification in the network address got is identical.
If the Subnet Identification in the network address got is identical, multiple invited user accounts are labeled as by S418 Abnormality.
In the present embodiment, after the corresponding multiple invited user accounts of the user account that inquires with get, obtain The account registion time of each invited user account is ranked up multiple invited user accounts according to account registion time, Multiple invited user accounts are detected according to the registration interval duration of invited user account two neighboring after sequence.Root When detecting invited user account as suspicious account according to registration interval duration, end is logged in further according to each invited user account The network address at end detects whether multiple invited user accounts are abnormal user account, so as to improve abnormal user account Detection accuracy.
As shown in figure 5, in one embodiment, the step of verifying invited user account, the step are further included after S310 Suddenly the following contents is specifically included:
S502 sends checking request to the invited user account institute registration terminal of label.
Specifically, the terminal 110 that the invited user account of the inquiry of server 120 label is logged in, according to the quilt of label User account generation checking request is invited, checking request is sent to the terminal 110 that the invited user account of label logged in. It can include identifying code in checking request.
S504 obtains the verification information that terminal is returned according to checking request.
Specifically, terminal 110 receive server 120 transmission checking request, according to checking request obtain user it is defeated The verification information of acquisition is sent to server 120 by the verification information entered, terminal 110.Verification information includes being invited for label Please user account, further include at least one of identifying code, identity information, finger print information, face image and facial feature information.
S506 verifies the invited user account of label according to verification information.
Specifically, server 120 parses verification information, carries after the verification information for receiving the return of terminal 110 The invited user account marked in verification information is taken, inquires the verification letter corresponding with the invited user account of label of storage The verification information received with the verification information stored is compared, if unanimously, being verified, if inconsistent, tests by breath Card does not pass through.
S508, if being passed through according to verification information to the invited user account of label, to the invited user account of label Cancel label.
Specifically, after server 120 is verified the invited user account of label according to verification information, to label Invited user account cancel the operation of label, and normally quilt is obtained after cancelling label to the invited user account of label Invite user account.
In the present embodiment, after by invited user account labeled as abnormality, to the invited user account of label The step of increasing verification, the invited user account of label is verified according to verification information, further improves abnormal user The accuracy of detection avoids that detection mistake occurs.
As shown in fig. 6, in one embodiment, the step of handling account registration request, the step are further included after S310 Specifically include the following contents:
Subnet Identification is added to abnormal Subnet List by S602.
Specifically, when the Subnet Identification in the network address that server 120 is got in judgement is identical, Subnet Identification is added It is added in abnormal Subnet List.The Subnet Identification stored in abnormal Subnet List is son where the terminal of registration abnormity user account The mark of net.
S604 receives account registration request.
Specifically, terminal 110 generates account registration request according to the log-on message of input, is specifically wrapped in account registration request Include network address, user account and the user password of terminal 110.The account registration request of generation is sent to service by terminal 110 Device 120.Server 120 receives the account registration request that terminal 110 is sent.
S606 extracts the network address in account registration request.
Specifically, server 120 parses account registration request, and the net in account registration request is extracted by parsing Network address.
S608, inquiry is with the presence or absence of Subnet Identification corresponding with the network address of extraction in abnormal Subnet List.
Specifically, server 120 extracts Subnet Identification from the network address of extraction, and server 120 obtains abnormal subnet The Subnet Identification extracted is inquired in list in abnormal Subnet List.
S610 if inquiring Subnet Identification corresponding with the network address extracted, refuses account registration request.
Specifically, if the Subnet Identification that server 120 is inquired and extracted in abnormal Subnet List, then it represents that extraction The corresponding terminal 110 of network address be in the corresponding subnet of Subnet Identification, the Subnet Identification be registration abnormity user account Place subnet, terminal 110 are the terminal of registration abnormity user account, then refuse the account registration request of the transmission of terminal 110.
In the present embodiment, according to subnet where terminal come judge terminal whether be registration abnormity user account terminal, keep away Exempt from after the account registration request for receiving terminal transmission, also the account registration request is further processed, reduced The resource spent by the account registration request is handled, reduces the number-of-registration of abnormal user account.
As shown in fig. 7, in one embodiment, providing a kind of detection device 700 of abnormal user account, the device is specific Including:User account acquisition module 702, user account enquiry module 704, network address acquisition module 706, Subnet Identification judge Module 708 and user account mark module 710.
User account acquisition module 702, for obtaining user account.
User account enquiry module 704, for inquiring multiple invited user accounts corresponding with user account.
Network address acquisition module 706, for obtaining the network address of each invited user account institute registration terminal.
Subnet Identification judgment module 708, for judging whether the Subnet Identification in the network address got is identical.
User account mark module 710 if the Subnet Identification in the network address that gets is identical, is invited multiple Please user account be labeled as abnormality.
In the present embodiment, multiple invited user accounts corresponding with the user account got are inquired, obtain each invited Please user account institute registration terminal network address, it is whether identical by judging to get Subnet Identification in network address, if Subnet Identification in the network address got is identical, then it represents that multiple invited user accounts are the terminals under same subnet It is logged in, multiple invited user accounts is labeled as abnormality.Without the use according to each invited user account Data are individually detected each invited user account, directly acquire the network of each invited user account institute registration terminal Address, the Subnet Identification in the network address got judge whether multiple invited user accounts are abnormal user account Number, improve the detection efficiency of abnormal user.
As shown in figure 8, in one embodiment, the detection device 700 of abnormal user account specifically further includes:Registion time Acquisition module 712, user account sorting module 714, interval duration obtain module 716 and interval duration comparison module 718.
Registion time acquisition module 712, for obtaining the corresponding account registion time of each invited user account.
User account sorting module 714, for being carried out according to the account registion time got to invited user account Sequence.
It is spaced duration and obtains module 716, when being registered for the account according to corresponding to the invited user account after sequence Between, obtain the registration interval duration of two neighboring invited user account.
Be spaced duration comparison module 718, for by registration interval duration compared with predetermined interval duration.
If network address acquisition module 720 is additionally operable to registration interval duration less than predetermined interval duration, acquisition is respectively invited to The corresponding log duration of user account.
Log duration judgment module 722, for judging whether the log duration extracted is less than default log duration.
If network address acquisition module 706, which is additionally operable to the log duration extracted, is less than default log duration, each quilt is obtained Invite the network address of user account institute registration terminal.
In the present embodiment, after the corresponding multiple invited user accounts of the user account that inquires with get, obtain The account registion time of each invited user account is ranked up multiple invited user accounts according to account registion time, Multiple invited user accounts are detected according to the registration interval duration of invited user account two neighboring after sequence.Root When detecting that invited user account is suspicious according to registration interval duration, further according to the net of each invited user account institute registration terminal Whether the multiple invited user accounts of network address detected are abnormal user account, so as to improve the detection of abnormal user account standard True rate.
As shown in figure 9, in one embodiment, the detection device 700 of abnormal user account specifically further includes:Checking request Sending module 724, verification information return to module 726, user account authentication module 728 and label and cancel module 730.
Checking request sending module 724, for sending checking request to the invited user account institute registration terminal of label.
Verification information returns to module 726, for obtaining the verification information that terminal is returned according to checking request.
User account authentication module 728, for being verified according to verification information to the invited user account of label.
Label cancels module 730, during for being verified according to verification information to the invited user account of label, to mark The invited user account of note cancels label.
In the present embodiment, after by invited user account labeled as abnormality, to the invited user account of label The step of increasing verification, the invited user account of label is verified according to verification information, further improves abnormal user The accuracy of detection avoids that detection mistake occurs.
As shown in Figure 10, in one embodiment, the detection device 700 of abnormal user account specifically further includes:Subnet mark Know add module 732, registration request receiving module 734, network address extraction module 736, Subnet Identification enquiry module 738 and note Volume request refusal module 740.
Subnet Identification add module 732, for Subnet Identification to be added to abnormal Subnet List.
Registration request receiving module 734, for receiving account registration request.
Network address extraction module 736, for extracting the network address in account registration request.
Subnet Identification enquiry module 738, for being inquired in abnormal Subnet List with the presence or absence of the network address with extraction Corresponding Subnet Identification.
Registration request refuses module 740, if for inquiring the network address with extraction in abnormal Subnet List During corresponding Subnet Identification, refuse account registration request.
In the present embodiment, according to subnet where terminal come judge terminal whether be registration abnormity user account terminal, keep away Exempt from after the account registration request for receiving terminal transmission, also the account registration request is further processed, reduced The resource spent by the account registration request is handled, reduces the number-of-registration of abnormal user account.
One of ordinary skill in the art will appreciate that realizing all or part of flow in above-described embodiment method, being can be with Relevant hardware is instructed to complete by computer program, which can be stored in a computer-readable storage and be situated between In matter, the program is when being executed, it may include such as the flow of the embodiment of above-mentioned each method.Wherein, aforementioned storage medium can be The non-volatile memory mediums such as magnetic disc, CD, read-only memory (Read-Only Memory, ROM) or random storage note Recall body (Random Access Memory, RAM) etc..
Each technical characteristic of embodiment described above can be combined arbitrarily, to make description succinct, not to above-mentioned reality It applies all possible combination of each technical characteristic in example to be all described, as long as however, the combination of these technical characteristics is not deposited In contradiction, it is all considered to be the range of this specification record.
Embodiment described above only expresses the several embodiments of the present invention, and description is more specific and detailed, but simultaneously It cannot therefore be construed as limiting the scope of the patent.It should be pointed out that those of ordinary skill in the art are come It says, without departing from the inventive concept of the premise, various modifications and improvements can be made, these belong to the protection of the present invention Range.Therefore, the protection domain of patent of the present invention should be determined by the appended claims.

Claims (12)

1. a kind of detection method of abnormal user account, the method includes:
Obtain user account;
Inquiry multiple invited user accounts corresponding with the user account;
Obtain the corresponding log duration of each invited user account;
The corresponding log duration of each invited user account is compared;
If the corresponding log duration of each invited user account is equal, it is pre- to judge whether the log duration got is less than If log duration;
If the log duration got is less than the default log duration, obtains each invited user account and stepped on Record the network address of terminal;
Judge whether the Subnet Identification in the network address got is identical;
If the Subnet Identification in the network address got is identical, the multiple invited user account is marked For abnormality.
2. if according to the method described in claim 1, it is characterized in that, the log duration got is less than described pre- If log duration, then the network address of each invited user account institute registration terminal is obtained, including:
If the log duration got is less than default log duration, the corresponding account registration of each invited user account is obtained Time;
Account registion time according to getting is ranked up invited user account;
Account registion time according to corresponding to the invited user account after sequence obtains two neighboring invited user account Registration interval duration;
By the registration interval duration compared with predetermined interval duration;
If the registration interval duration is less than the predetermined interval duration, obtains each invited user account and log in end The network address at end.
3. method according to claim 1 or 2, which is characterized in that described to mark the multiple invited user account After abnormality, further include:
Checking request is sent to the invited user account institute registration terminal of label;
Obtain the verification information that the terminal is returned according to the checking request;
The invited user account of the label is verified according to the verification information;
If being verified, label is cancelled to the invited user account of the label.
4. method according to claim 1 or 2, which is characterized in that described to mark the multiple invited user account After abnormality, further include:
The Subnet Identification is added to abnormal Subnet List;
Receive account registration request;
Extract the network address in the account registration request;
Inquiry is with the presence or absence of Subnet Identification corresponding with the network address of extraction in the abnormal Subnet List;
If inquiring, refuse the account registration request.
5. a kind of detection device of abnormal user account, which is characterized in that described device includes:
User account acquisition module, for obtaining user account;
User account enquiry module, for inquiring multiple invited user accounts corresponding with the user account;
Log duration acquisition module, for obtaining the corresponding log duration of each invited user account;
Log duration judgment module, for the corresponding log duration of each invited user account to be compared;Described When the corresponding log duration of each invited user account is equal, when judging whether the log duration got is less than default log in It is long;
Network address acquisition module, for when the log duration got is less than the default log duration, obtaining each The network address of invited user account institute registration terminal;
Subnet Identification judgment module, for judging whether the Subnet Identification in the network address got is identical;
User account mark module, will be described more if the Subnet Identification in the network address got is identical A invited user account is labeled as abnormality.
6. device according to claim 5, which is characterized in that described device further includes:
Registion time acquisition module, for when the log duration got is less than the default log duration, obtaining each The corresponding account registion time of the invited user account;
User account sorting module, for being ranked up according to the account registion time got to invited user account;
It is spaced duration and obtains module, for the account registion time according to corresponding to the invited user account after sequence, obtain The registration interval duration of two neighboring invited user account;
Be spaced duration comparison module, for by the registration interval duration compared with predetermined interval duration;
If the network address acquisition module is additionally operable to the registration interval duration less than the predetermined interval duration, each institute is obtained State the network address of invited user account institute registration terminal.
7. device according to claim 5 or 6, which is characterized in that described device further includes:
Checking request sending module, for sending checking request to the invited user account institute registration terminal of label;
Verification information returns to module, for obtaining the verification information that the terminal is returned according to the checking request;
User account authentication module, for being verified according to the verification information to the invited user account of the label;
Label cancels module, right during for being verified according to the verification information to the invited user account of the label The invited user account of the label cancels label.
8. device according to claim 5 or 6, which is characterized in that described device further includes:
Subnet Identification add module, for the Subnet Identification to be added to abnormal Subnet List;
Registration request receiving module, for receiving account registration request;
Network address extraction module, for extracting the network address in the account registration request;
Subnet Identification enquiry module, for being inquired in the abnormal Subnet List with the presence or absence of corresponding with the network address of extraction Subnet Identification;
Registration request refuses module, if corresponding with the network address extracted for being inquired in the abnormal Subnet List Subnet Identification when, refuse the account registration request.
9. a kind of computer readable storage medium, is stored thereon with computer program, which is characterized in that the computer program quilt Processor realizes following steps when performing:
Obtain user account;
Inquiry multiple invited user accounts corresponding with the user account;
Obtain the corresponding log duration of each invited user account;
The corresponding log duration of each invited user account is compared;
If the corresponding log duration of each invited user account is equal, it is pre- to judge whether the log duration got is less than If log duration;
If the log duration got is less than the default log duration, obtains each invited user account and stepped on Record the network address of terminal;
Judge whether the Subnet Identification in the network address got is identical;
If the Subnet Identification in the network address got is identical, the multiple invited user account is marked For abnormality.
10. storage medium according to claim 9, which is characterized in that if the log duration got is less than The default log duration then obtains the network address of each invited user account institute registration terminal, including:
If the log duration got is less than default log duration, the corresponding account registration of each invited user account is obtained Time;
Account registion time according to getting is ranked up invited user account;
Account registion time according to corresponding to the invited user account after sequence obtains two neighboring invited user account Registration interval duration;
By the registration interval duration compared with predetermined interval duration;
If the registration interval duration is less than the predetermined interval duration, each invited user account of acquisition is performed The step of network address of institute's registration terminal.
11. storage medium according to claim 9 or 10, which is characterized in that described by the multiple invited user account Labelled notation is after abnormality, the computer program realizes following steps when being executed by processor:
Checking request is sent to the invited user account institute registration terminal of label;
Obtain the verification information that the terminal is returned according to the checking request;
The invited user account of the label is verified according to the verification information;
If being verified, label is cancelled to the invited user account of the label.
12. storage medium according to claim 9 or 10, which is characterized in that described by the multiple invited user account Labelled notation is after abnormality, the computer program realizes following steps when being executed by processor:
The Subnet Identification is added to abnormal Subnet List;
Receive account registration request;
Extract the network address in the account registration request;
Inquiry is with the presence or absence of Subnet Identification corresponding with the network address of extraction in the abnormal Subnet List;
If inquiring, refuse the account registration request.
CN201710090744.0A 2017-02-20 2017-02-20 The detection method and device of abnormal user account Active CN107135195B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710090744.0A CN107135195B (en) 2017-02-20 2017-02-20 The detection method and device of abnormal user account

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710090744.0A CN107135195B (en) 2017-02-20 2017-02-20 The detection method and device of abnormal user account

Publications (2)

Publication Number Publication Date
CN107135195A CN107135195A (en) 2017-09-05
CN107135195B true CN107135195B (en) 2018-06-08

Family

ID=59721805

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710090744.0A Active CN107135195B (en) 2017-02-20 2017-02-20 The detection method and device of abnormal user account

Country Status (1)

Country Link
CN (1) CN107135195B (en)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107733883B (en) * 2017-10-09 2020-08-04 武汉斗鱼网络科技有限公司 Method and device for detecting account numbers registered in batches
CN108282490B (en) * 2018-02-09 2021-07-09 深圳壹账通智能科技有限公司 Processing method and device for abnormal registered user, computer equipment and storage medium
CN108596653A (en) * 2018-04-04 2018-09-28 顺丰科技有限公司 A kind of discount coupon is abnormal to use detecting system, method, equipment and storage medium
CN109660513A (en) * 2018-11-13 2019-04-19 微梦创科网络科技(中国)有限公司 A kind of method and device based on Storm cluster identification problem account
CN109918279B (en) * 2019-01-24 2022-09-27 平安科技(深圳)有限公司 Electronic device, method for identifying abnormal operation of user based on log data and storage medium
CN111224932B (en) * 2019-10-15 2022-01-04 平安科技(深圳)有限公司 User management method and device of server out-of-band management system
CN111400678A (en) * 2020-03-06 2020-07-10 北京奇艺世纪科技有限公司 User detection method and device
CN111400677A (en) * 2020-03-06 2020-07-10 北京奇艺世纪科技有限公司 User detection method and device
CN111681034A (en) * 2020-04-29 2020-09-18 五八有限公司 Method and device for distributing resource information
CN112351030B (en) * 2020-11-04 2024-01-05 广州腾讯科技有限公司 Data processing method and computer equipment
CN113271315A (en) * 2021-06-08 2021-08-17 工银科技有限公司 Virtual private network abnormal use detection method and device and electronic equipment
CN113312560B (en) * 2021-06-16 2023-07-25 百度在线网络技术(北京)有限公司 Group detection method and device and electronic equipment
CN114553738A (en) * 2022-02-25 2022-05-27 支付宝实验室(新加坡)有限公司 Abnormality detection method and apparatus

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103905532A (en) * 2014-03-13 2014-07-02 微梦创科网络科技(中国)有限公司 Microblog marketing account recognition method and system
CN105262760A (en) * 2015-10-30 2016-01-20 北京奇虎科技有限公司 Method and device for preventing action of maliciously visiting login/register interface
CN105550175A (en) * 2014-10-28 2016-05-04 阿里巴巴集团控股有限公司 Malicious account identification method and apparatus
CN105791255A (en) * 2014-12-23 2016-07-20 阿里巴巴集团控股有限公司 Method and system for identifying computer risks based on account clustering
CN105808988A (en) * 2014-12-31 2016-07-27 阿里巴巴集团控股有限公司 Method and device for identifying exceptional account

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103905532A (en) * 2014-03-13 2014-07-02 微梦创科网络科技(中国)有限公司 Microblog marketing account recognition method and system
CN105550175A (en) * 2014-10-28 2016-05-04 阿里巴巴集团控股有限公司 Malicious account identification method and apparatus
CN105791255A (en) * 2014-12-23 2016-07-20 阿里巴巴集团控股有限公司 Method and system for identifying computer risks based on account clustering
CN105808988A (en) * 2014-12-31 2016-07-27 阿里巴巴集团控股有限公司 Method and device for identifying exceptional account
CN105262760A (en) * 2015-10-30 2016-01-20 北京奇虎科技有限公司 Method and device for preventing action of maliciously visiting login/register interface

Also Published As

Publication number Publication date
CN107135195A (en) 2017-09-05

Similar Documents

Publication Publication Date Title
CN107135195B (en) The detection method and device of abnormal user account
CN107800678B (en) Method and device for detecting abnormal registration of terminal
CN108183924A (en) A kind of login validation method and terminal device
CN109951436B (en) Trusted terminal verification method and device
CN106550031A (en) The method and device of data backup
CN106549974A (en) Prediction the social network account whether equipment of malice, method and system
CN104320375B (en) A kind of method and apparatus for preventing from illegally registering
CN113032792B (en) System business vulnerability detection method, system, equipment and storage medium
CN105141628B (en) A kind of method and device for realizing push
CN106375279A (en) Attendance checking method, device and system based on mobile equipment
CN105992204A (en) Access authentication method of applications of mobile intelligent terminal and device
CN108076056A (en) Cloud server login method and device
CN105260779A (en) Tag based personalization
CN104980393B (en) Method of calibration, system, server and terminal
CN106385403B (en) A kind of the user account register method and relevant device of self-help print equipment
CN107563360A (en) Information acquisition method and device
CN107332804A (en) The detection method and device of webpage leak
CN107241292A (en) Leak detection method and device
CN108540293A (en) A kind of identity identifying method and device
CN104462934B (en) A kind of information processing method and electronic equipment
CN112615873B (en) Internet of things equipment safety detection method, equipment, storage medium and device
CN111611465B (en) Product detection system, method, device, computer equipment and storage medium
CN106874748A (en) A kind of method and apparatus that user data is provided
CN105516057B (en) Data processing method, device and system
CN108092947A (en) A kind of method and device that identity discriminating is carried out to third-party application

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
REG Reference to a national code

Ref country code: HK

Ref legal event code: DE

Ref document number: 1238429

Country of ref document: HK

GR01 Patent grant
GR01 Patent grant
REG Reference to a national code

Ref country code: HK

Ref legal event code: GR

Ref document number: 1238429

Country of ref document: HK